First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 12811
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Daniel Ahlberg (RETIRED) <aliz@gentoo.org>
Add CC:
CC:
URL:
Summary:
Status Whiteboard:
Keywords:

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 12811 depends on: Show dependency tree
Bug 12811 blocks:
Votes: 0    Show votes for this bug    Vote for this bug

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2002-12-27 18:05 0000
Buffer overflow in PHP "wordwrap" function 
 
From:  
"David F. Skoll" <dfs@roaringpenguin.com> 
 
 
To:  
bugtraq@securityfocus.com 
 
 
Date:  
Yesterday 22.43.44 
 
 
 
Message was signed with unknown key 0x13624131. 
The validity of the signature cannot be verified. 
 
 
There is a buffer overflow in PHP's built-in "wordwrap" function 
for PHP versions greater than 4.1.2 and less than 4.3.0. 
 
Please see http://bugs.php.net/bug.php?id=20927 for details. 
 
If you use the wordwrap() function on user-supplied input, a 
specially-crafted input can overflow the allocated buffer and 
overwrite the heap.  Exploit looks very difficult, but still 
theoretically possible. 
 
Status: 
 
Bug cause discovered: 10 Dec 2002 
PHP team notified:    10 Dec 2002 
Bug fixed in CVS:     12 Dec 2002 
PHP 4.3.0 released:   27 Dec 2002 
 
Kudos to the PHP team for their extremely rapid reaction. 
 
Recommendations: 
 
Don't upgrade from 4.1.2 if you are certain there are no security problems 
with your 4.1.2 setup and you may be vulnerable to the wordwrap() bug. 
 
Otherwise, upgrade to 4.3.0 
 
-- 
David F. Skoll 
 
Roaring Penguin Software Inc. | http://www.roaringpenguin.com 
GPG fingerprint: 58BB 6D86 6F6F 84D0 2C89  59D1 CD1C CAEE 1362 4131 
GPG public key:  http://www.roaringpenguin.com/dskoll-key-2003.txt ID: 13624131 
 
 
End of signed message

------- Comment #1 From Ryan Phillips (RETIRED) 2002-12-30 15:14:34 0000 -------
4.3.0 has been added to portage for testing.

------- Comment #2 From Alessandro Pisani 2003-01-08 17:10:42 0000 -------
php 4.3.0 had been unmasked in portage, so I guess this can be closed...

------- Comment #3 From Daniel Ahlberg (RETIRED) 2003-01-17 04:56:08 0000 -------
glsa sent 

First Last Prev Next    No search results available      Search page      Enter new bug